VendorsWpDevArtbooking_calendarall versions
Vulnerabilities

WpDevArt Booking Calendar

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2022-3982
Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload
Published 2022-12-12 · Modified
9.8EPSS 0.045
CVE-2022-47428
WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.7 is vulnerable to SQL Injection
Published 2023-11-06 · Modified
9.8EPSS 0.007
CVE-2023-24373
WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability
Published 2024-06-03 · Analyzed
9.8EPSS 0.004
CVE-2023-24407
WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Broken Access Control vulnerability
Published 2024-12-09 · Modified
8.8EPSS 0.005
CVE-2018-10363
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.
Published 2018-06-13 · Modified
7.5EPSS 0.014
CVE-2024-10856
Booking Calendar WpDevArt <= 3.2.19 - Authenticated (Contributor+) SQL Injection
Published 2024-12-24 · Analyzed
6.5EPSS 0.005
CVE-2022-47438
WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.3 is vulnerable to Cross Site Scripting (XSS)
Published 2023-03-29 · Modified
5.9EPSS 0.004
CVE-2023-24388
WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.3 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-02-17 · Modified
5.4EPSS 0.002